background image

E-Payment

  

            

MagIC

3

 M-series Handset  -  MAINTENANCE MANUAL 

INTRODUCTION 

Ref: 22000-02-MAN-I-08010 

 

 

August 2009 

 

 

 

                       1/35 

Copyright Gemalto – 2008 

No disclosure to a third party without prior written consent of Gemalto

 

 

 

Point of Sales Terminals 

MagIC

3

 M-series Handset 

 

MAINTENANCE MANUAL 

 

Version 2.0  -  August 2009

 
 

Summary of Contents for MagIC3 C-series

Page 1: ...MANUAL INTRODUCTION Ref 22000 02 MAN I 08010 August 2009 1 35 Copyright Gemalto 2008 No disclosure to a third party without prior written consent of Gemalto Point of Sales Terminals MagIC3 M series Handset MAINTENANCE MANUAL Version 2 0 August 2009 ...

Page 2: ...ritten permission from Gemalto E Payment and are subject to use copying and disclosure restrictions contained in a agreement with Gemalto E Payment These materials are to be used only for the intended purpose agreed upon in the related contract with Gemalto E Payment IN NO EVENT SHALL GEMALTO E PAYMENT BE LIABLE FOR SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH OR ARISING FROM THE U...

Page 3: ...prior written consent of Gemalto MODIFICATION SHEET Date Version Modifications Aug 2008 1 0 Draft Oct 2008 1 1 Release Oct 2008 1 2 Updated III MI16 Elastomeric replacement August 2009 2 0 Updated I 2 Updated II 2 12 SECURITY ALERT procedure Added II 3 0 SECURITY ALERT SP status register Updated III MI5 MI7 MI9 MI11 MI15 Updated LITHIUM_BAT voltage threshold replacement ...

Page 4: ...1 Methodology 18 1 2 Safety regulation 18 1 3 Special tools and test equipment 18 1 4 Procedure 19 2 Troubleshooting Instructions 20 2 1 BATTERY PACK failure 20 2 2 POWER SUPPLY failure 21 2 3 DISPLAY failure 22 2 4 KEYBOARD failure 22 2 5 PRINTER failure 23 2 6 MAGNETIC READER failure 24 2 7 CUSTOMER SMART CARD READER failure 25 2 8 SAM READER SIM sized failure 25 2 9 GSM INTERFACE failure 26 2 1...

Page 5: ...ow to find the root cause of failures III Maintenance containing replacement procedures for all parts that can be exchanged during Maintenance level 2 operation It mainly makes reference to the Maintenance software MagIC3 Diag RI 02 1 1 References RI 01 22000 02 MAN I 08011 Part III MAINTENANCE RI 02 15200 00 MAN S 07001 Maintenance software MagIC3 Diag User Manual 1 2 MagIC3 Diag software You hav...

Page 6: ... is connected to the Main board through 30 pin board to board connector The Main PCB supports the MP Main Processor memories RAM Flash EEPROM Power Charge manager and connectors for devices SAM readers mag stripe rdr printer radio module battery pack external contacts with the Base USBA power supply jack A secure box mades of PCB that covers sensitive signals components of the keyboard board The H...

Page 7: ...to 2008 No disclosure to a third party without prior written consent of Gemalto 1 Printer 6 Contacts with Base 11 USB Device 2 Display 7 SIM sized reader for GSM 12 Power Supply 3 Keyboard 8 Battery pack 4 Smart Card Reader 9 Reset button 5 Magnetic Stripe Reader 10 2 x SIM sized readers for application purpose 2 3 5 1 4 6 7 11 10 8 12 9 ...

Page 8: ...RAM 100 kbytes h w TRNG TDES RSA accelerator Intrusion sensors Protection against SPA DPA attacks Environment protection systems Voltage frequency temperature UV SIM1 to SIM2 smart card readers Customer smart card reader Intrusion switches mesh sensors Battery backup Graphic display Graphic display Buzzer Keyboard EEPROM FLASH EPROM SDRAM Magnetic stripe d Driver SIM GSM Li ion Battery pack Fuel g...

Page 9: ...56 Kb EEPROM 96 Kb RAM 4 Kb crypto RAM 32 Kb ROM RTC System timers Communication ports 1x ISO7816 controller 1x ISO7816 multiplexed to address up to 4 SAM in our application DES3 AES SHA crypto multiplier RSA DSA key generation ECC True random number generator Security features 256 bits for key storage battery backup Dedicated hardware for protection against SPA DPA attacks Active shield intrusion...

Page 10: ...e equipped with either head allowing 2 tracks reading ISO1 2 2 3 or head allowing 3 tracks reading for ISO 1 2 3 Head 2 or 3 tracks is connected to the PCB via a 7 point connector Note The cards can be read in both way it can be introduced from up to down or from down to up 2 2 6 Smart card interfaces The AT91SO101 includes a smart card solution fully compatible with ISO7816 EMV2000 standards The ...

Page 11: ... Display MAIN CHARACTERISTICS Backlight Optional backlight equipped in standard configuration Icon area NO Active area 54 18 w x 28 58 h mm Dot Dot size 128 x 64 dots 0 38 x 0 38 mm pitch 0 40 x 0 40 Contrast Automatic temperature adjustment integrated to the display with possibility to control it by software Lcd type Backlight version FSTN White Positive Transflective No backlight version STN Yel...

Page 12: ...Processor A lithium button cell of 3V 230mA h is used for the backup of the Secure Processor It is located on the keyboard pcb and is not accessible Its replacement requires the opening of the terminal triggering the tampering mechanism leading to the erasure of the banking keys When the Terminal is power off or in case of Vcc failure the SP is backed up via the battery lithium cell and the follow...

Page 13: ...k of 7 4V 1150mA h is used to maintain the Handset functional when not power on typically the case when it is not on its Base when not directly power on via its jack plug The Li ion battery set consist in fact on 2 prismatic elements of 3 7V each This pack integrates a fuel gauge used for charge management and a protection circuit to detect over under voltage It is located on the bottom side of th...

Page 14: ...ardware trigger like from communication devices in any case it is software dependent 2 2 18 Communication with the Base It is done via an USBh Base can be considered like a Hub on which peripherals are connected to Physically it consists of 4 electrical contacts located on the bottom side of the Handset D D Gnd Vin When Terminal put on its Base communication is done via this way 2 2 19 Tamper dete...

Page 15: ...the front and the bottom covers the whole is maintained in position by screws Mechanical construction is designed in order to prevent access to sensitive components Note When tampering the Handset shall be put back into operation using the Unlocking tool 2 2 20 Mechanical element characteristics Plastic is ABS UL94 HB 2 Other pieces are UL94 HB minimum Note Evolution on going to introduce Handset ...

Page 16: ...ge of selecting the correct application for each transaction It also puts in common transactional services such as currencies accounts total merchants and messages management It is up to the AM to handle idle screen and all terminal management menus to setup terminal date printer and display contrast ticket headers and footers remote downloading parameters etc The secure firmware is entirely conta...

Page 17: ... M series Handset MAINTENANCE MANUAL Chapter 1 DESCRIPTION Ref 22000 02 MAN I 08010 August 2009 Ch 1 17 35 Copyright Gemalto 2008 No disclosure to a third party without prior written consent of Gemalto END OF CHAPTER 1 ...

Page 18: ...o the troubleshooting procedures relate to procedures listed in the MAINTENANCE part chapter 3 of MAINTENANCE MANUAL 1 1 2 Reference T References T relate to the auto test that can be run with Maintenance Software MagIC3 Diag refer to RI 02 for details 1 2 Safety regulation When the equipped boards are manipulated these recommendations must be followed to prevent electrostatic discharges Use anti ...

Page 19: ...e sure the software configuration is coherent and operational You are aware of information related to ELASTOMERIC by reading MI 16 Before opening the Handset make sure that cables power supply and USB device are disconnected The Handset must be put in power off before opening it If you open the Handset during repair operation Get into the habit of checking the LITHIUM_BAT voltage We recommend to c...

Page 20: ...present change the PCB_MAINBOARD by a new one MI 13 2 1 3 Battery pack control Procedure Ref 1 Check BATTERY_PACK cable and connector 2 Check voltage Vbat 7 2V Vbat 8 4V The Handset must be operational 6 8V Vbat 7 2V Vbat is under the AM shut down trigger The AM goes in power off when Vbat 7 2V Vbat 6 8V Vbat is under the OS shut down trigger The OS goes in power off when Vbat 6 8V OS shut down se...

Page 21: ...ndset make sure you reproduce the issue with a reference power supply 5 If the failure disappears change the power supply even though the power supply seems the root cause check the power jack of the PCB_MAINBOARD it might be the problem 6 If the failure is still present change the PCB_MAINBOARD by a new one MI 13 2 2 3 PSU control 1 Disconnect the power supply from the terminal 2 Connect the powe...

Page 22: ...LAY if damaged MI 5 MI 7 2 If the failure is still present change the DISPLAY by a new one if DISPLAY already changed in 1 goto 3 directly MI 7 3 If the failure is still present change the PCB_KEYBOARD by a new one MI 5 2 4 KEYBOARD failure 2 4 1 Symptoms No response of the terminal when a key is pressed 2 4 2 Procedure Keyboard failure Ref 1 Before opening the Handset verify that no key is blocke...

Page 23: ...ening the Handset check if the PAPER_ROLL and PLATEN_ROLLER are present and well positioned verify that the PRINTER_LID is correctly closed MI 2 2 Check Printer flex is not damaged Printer flex is well connected to the PCB_MAINBOARD PRINTER is correctly positioned in the HANDSET_BOTTOM PRINTER is correctly fixed to its support If need reposition the piece and or change the PRINTER flex damaged MI ...

Page 24: ...of an error message on the display after card swiped 2 6 2 Procedure Magnetic reader failure Ref 1 Check Magnetic reader connector is in place Cable is not damaged MAG_HEAD support is correctly inserted in the HANDSET_BOTTOM MAG_HEAD is correctly inserted in the MAG_HEAD support If need reposition the piece and or change the MAG_HEAD if damaged MI 9 2 If the failure is still present change the MAG...

Page 25: ... them if need MI 4 MI 5 2 If the failure is still present change the PCB_KEYBOARD by a new one MI 5 2 8 SAM READER SIM sized failure 2 8 1 Symptoms SIM sized cannot be detected 2 8 2 Procedure SAM reader SIM sized failure Ref 1 Verify that the 6 screws are correctly tighten Check SIM slot foreign body fatty substance Clean the piece if possible MI A MI 13 2 If the failure is still present change t...

Page 26: ...lure is still present change the PCB_MAINBOARD by a new one MI 13 CASE GPRS SIM NOK Ref 1 Verify that the 6 srews are correctly tighten Check GSM SIM connector foreign body fatty substance dust etc Clean the piece if possible MI 13 2 If the failure is still present change the PCB_MAINBOARD by a new one MI 13 3 If the failure is still present change the HANDSET_BOTTOM by a new one steps 2 3 can be ...

Page 27: ...e USB cable is not damaged Check the USB connector 2 If Ok change the PCB_MAINBOARD by a new one MI 13 2 11 BASE CONTACT INTERFACE failure 2 11 1 Symptoms Base is not detected anymore Communication failure between Handset and Base 2 11 2 Procedure Base contact interface failure Ref 1 Before opening the Handset make sure you reproduce the issue with a reference Base a reference power supply contect...

Page 28: ...portant information you have to know before starting Some switches and meshs are interlaced by design It means that when the Secure Processor records a mesh issue the root cause can be also one of the switches Besides a switch is routed through the DISPLAY flex it means that DISPLAY can raise a switch issue too Make sure that the root cause does not come from key issues AUTH_SP AUTH_CUST keys must...

Page 29: ...ly opened Change the KEYPAD KEYPAD is certainly the root cause but since Terminal is open Check the PCB_KEYBOARD on a reference Terminal a golden sample and change it if failure occurs Verify that the DISPLAY flex is correctly connected MI 6 MI 5 CASE Mesh opened Ref 1 Mesh or and Switch is currently opened Check the GRID_MESH_BOX continuity If the continuity fails change GRID_MESH_BOX ELASTOMERIC...

Page 30: ...th as indication Tampered Although Meshs Switches are currently OK you face to a transient phenomenon that occurs on field In this case manage this problem as if the Mesh or and Switch was currently opened Note UKSR Curr information are reset when you Unlock the Terminal It means above analyse must be done before Unlocking the Terminal CASE System clock is lost Ref 1 Check LITHIUM_BAT voltage If V...

Page 31: ...on If the security has been tampered a SECURITY ALERT message will be displayed for few seconds at boot time Unlike X series there is no more Key Icon on the Display to indicate when the security has been triggered Below content gives you some detailed information about Security Alert This can be usefull when you did not success by following procedure described in 2 12 Remember always starting by ...

Page 32: ...aningless UKSR Sav 0x00000000 Value of the UKSR Curr before the last Unlock operation Please read UKSR Curr to understand usefulness of UKSR Sav Note that b0 of UKSR Sav is always 0 UKSR Curr 0x00000001 This register gives some information about the last event impacting the security state When at least AUTH_SP and AUTH_CUST have been loaded and no attack has been detected the UKSR Curr must be equ...

Page 33: ...load only AUTH_SP without AUTH_CUST this bit will not be reset 0x08 VBACKUPRST Lithium cell power has been cut for few seconds or more Note on C series as soon as you open the terminal this bit is set to 1 due to the lithium cell power that is cut when the board to board connector is opened 3 3 Interpreting UKSR SECIRQ values All those values can be added to another one of the same category Ex SEC...

Page 34: ...k since last unlock SECIRQ Sav xx xx xx xx NOT RELEVANT SECIRQ Cur 00 00 00 00 All security triggers are currently Ok SP Status 2 SECURITY ALERT UKSR Sav 01 00 00 00 Not relevant in this example UKSR Curr 00 00 00 03 Here we can see that SOFT is set it means that the terminal underwent a RESET process and that since this operation AUTH_SP AUTH_CUST keys have not been reloaded SECIRQ Sav xx xx xx x...

Page 35: ...eries Handset MAINTENANCE MANUAL Chapter 2 TROUBLESHOOTING Ref 22000 02 MAN I 08010 August 2009 Ch 2 35 35 Copyright Gemalto 2008 No disclosure to a third party without prior written consent of Gemalto END OF CHAPTER 2 4 3 ...

Reviews: